Keep the Intelligence. Lose the Leak.
specVIO is a privacy layer that sits between you and every AI you use. It reads your prompt before ChatGPT, Claude, or any model does — catching API keys, emails, phone numbers, and other identifiers, and stripping them out before you hit send. Entirely local. Nothing you paste ever leaves your device.
V.I.O. — VERIFY → ISOLATE → OBFUSCATE
- 0
- BYTES TRANSMITTED
- 100%
- ON-DEVICE
- REAL-TIME
- DETECTION
You're not careless. The paste box just doesn't warn you.
Every one of these is a normal, harmless-feeling thing to type into a chatbot. Here's what actually goes with it — and what it looks like sanitized.
The Resume You Asked It to Polish
You paste your resume and cover letter into a chatbot to tighten the wording before applying.
GOES WITH IT:[✓] Sanitized locally — you still get the polished resume, minus the identifiers a bot never needed.
The Symptom You Typed at 2am
You describe a health concern to get a plain-language explanation before your appointment, name and all.
GOES WITH IT:[✓] Sanitized locally — you still get the explanation, without attaching it to your identity.
The Email Thread You Pasted for Context
You copy a work email chain in so the assistant can help you draft a reply that fits the conversation.
GOES WITH IT:[✓] Sanitized locally — you still get the draft, without handing over the whole thread.
These are the everyday version. For what happens at the extreme — real leaks, lawsuits, and AI malfunctions that made the news — see the incident log.
How Exposed Are You?
Five questions about how you actually use AI chatbots. No data leaves your browser — the score is calculated on your device.
How often do you paste real text into AI chatbots?
Watch V.I.O. catch a leak, live
Paste a real prompt into the interactive sandbox and watch API keys, emails, and other identifiers get caught and redacted in your browser — nothing you type ever leaves your machine.
[ Launch Web Sandbox → ]Audit Your Chat History
Not just one prompt — upload a full data export (or paste the transcript) and see everything already tied to your identity across it. The file is read in your browser tab; it's never uploaded anywhere.
[ How do I get this file? ]
- 1. Click your profile icon → Settings
- 2. Data Controls → Export Data → confirm
- 3. Wait for the email from OpenAI (usually a few minutes)
- 4. Download the .zip within 24 hours — it contains conversations.json
- 1. Click your profile icon (bottom-left) → Settings
- 2. Privacy → Export Data → confirm
- 3. Wait for the email from Anthropic (usually a few minutes)
- 4. Download the .zip within 24 hours — it contains conversations.json
- 1. Go to takeout.google.com and sign in
- 2. Deselect all → check "My Activity"
- 3. Open "All activity data included" → keep only "Gemini Apps"
- 4. Create export → wait for the email (hours to a few days)
- 5. Download within 7 days — contains your Gemini prompts as JSON
- 1. Go to privacy.microsoft.com and sign in
- 2. Privacy → Empower your productivity → Copilot
- 3. Your Copilot app activity history → Copilot apps
- 4. Export all activity history — downloads as a .csv
Microsoft doesn't offer a full JSON export yet — this CSV is the closest official option. Copy-pasting a single conversation into a .txt file works too.
- 1. Go to grok.com and sign in
- 2. Profile icon → Settings → Data Controls
- 3. Choose to download your data
- 4. Wait for it to prepare, then download the file
Other platforms usually offer something similar under Settings → Privacy or Data Controls. Once you've unzipped the download, upload or drop the conversations.json file below.
- [Phone Numbers] …rah Connor, direct line (415) 555-0134 if they need to call me…
- [Social Security Numbers] …. Here's my SSN for it: 219-09-9999. Can you format it into…
- [API Keys & Tokens] …staging API? The key is sk-live-7f3ac91b2e4d0091. ChatGPT: Here's an exa…
- [Email Addresses] …my personal email too — sarah.connor@resistance.org ChatGPT: Done — I've in…
Zero-Knowledge Engineering
Built on a strict local-first philosophy. Your prompts, code blocks, and documents never touch our servers.
The Prompt Sanitizer
Automatically scrubs API keys, connection strings, corporate names, and credentials — natively, on-device.
Adjustable Risk Sensitivity
Dial detection from light to strict — every keystroke is scanned live, so you always see what's at risk before you hit send.